arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.14074cs.AI

Mandato:通过密码学链式审计追踪对AI智能体操作执行数字签名授权的协议级机制

Mandato: Protocol-Level Enforcement of Digitally Signed Mandates on AI Agent Actions with Cryptographically Chained Audit Trails

Giovanni Racioppi

AI总结:

研究针对AI智能体工具调用授权缺乏协议级保障与可审计性的问题,提出Mandato治理代理,通过密码学链式审计追踪实现协议级数字签名授权执行,适配欧盟多项法规并给出评估计划。

AI中文摘要:

AI智能体日益通过诸如模型上下文协议(Model Context Protocol,MCP)这类标准化工具调用协议作用于外部系统,但目前尚无基础设施层将其行为限制在主体可验证授权的范围内:授权逻辑存在于应用代码中,既未签名也无法独立审计,生成的日志缺乏证据效力。我们提出Mandato,这一治理代理可在协议层对智能体操作执行数字签名授权。授权是一种机器可读、经密码学签名的授权制品,规定智能体可调用的工具、参数约束与上下文条件、有效期以及代表对象;代理会针对适用的授权链评估每一次工具调用,同步阻止不符合要求的调用,并将每一项决策(允许、拒绝及对应证据)记录在仅追加、哈希链式的审计日志中,该日志专为证据用途设计,且定期通过合格时间戳锚定。授权刻意借鉴了民法中的授权委托制度,使该制品不仅工程师能理解,律师和审计人员也能读懂。我们给出授权模型及其决策语义、作为MCP透明代理的参考架构(含分离的决策与执行点),并将该机制映射到欧盟AI法案第12条和第14条、GDPR问责制、NIS2指令及eIDAS 2法规,还提供了通过合格信任服务提供商(Qualified Trust Service Providers,QTSP)获取合格证明的路线图。我们描述了参考系统的实现状态以及涵盖执行开销、审计完整性和防篡改证据验证成本的定量评估计划。

英文摘要:

AI agents increasingly act on external systems through standardized tool-calling protocols such as the Model Context Protocol (MCP), yet no infrastructure layer constrains their actions to what a principal has verifiably authorized: authorization logic lives in application code, is neither signed nor independently auditable, and the resulting logs lack evidentiary value. We present Mandato, a governance proxy that enforces digitally signed mandates on agent actions at the protocol level. A mandate is a machine-readable, cryptographically signed authorization artifact specifying which tools an agent may invoke, under which parameter constraints and contextual conditions, for how long, and on whose behalf; the proxy evaluates every tool call against the applicable mandate chain, blocks non-conforming calls in line, and records every decision -- permit, deny, and the evidence for each -- in an append-only, hash-chained audit log designed for evidentiary use and periodically anchored via qualified timestamps. The mandate is deliberately modeled on the civil-law institution of delegation of authority, making the artifact legible to lawyers and auditors, not only to engineers. We give the mandate model and its decision semantics, the reference architecture as an MCP-transparent proxy with separated decision and enforcement points, and a mapping of the mechanism onto EU AI Act Articles 12 and 14, GDPR accountability, NIS2, and eIDAS 2, including a roadmap to qualified attestation through Qualified Trust Service Providers (QTSPs). We describe the implementation status of the reference system and a quantitative evaluation plan covering enforcement overhead, audit completeness, and tamper-evidence verification cost.

补充信息

↑